7Learnings · Authentication Profile

7Learnings Authentication

Authentication

7Learnings declares 3 security scheme(s) across its OpenAPI definitions.

CompanyRetailPricingPrice OptimizationPredictive PricingDemand ForecastingMachine LearningE-CommercePerformance MarketingData IntegrationGermanySoftware-as-a-Service
Methods: Schemes: 3 OAuth flows: API key in:

Security Schemes

oauth2
· flows:
interactive
delegated

Source

Authentication Profile

7learnings-authentication.yml Raw ↑
generated: '2026-09-05'
method: probed
source: >-
  https://7learnings.com/.well-known/oauth-authorization-server,
  https://7learnings.com/.well-known/oauth-protected-resource,
  https://7learnings.com/security-compliance-data-protection/,
  https://7learnings.com/changelog/
summary: >-
  7Learnings publishes no public REST API and therefore no OpenAPI securitySchemes. Two
  authentication surfaces are nevertheless documented or observable: OAuth 2.0 on the MCP
  endpoint served from 7learnings.com, and SSO/MFA/passwordless sign-in on the 7Learnings
  Steering App. Customer data integration is authenticated per-connection, per-customer,
  by the credentials of the transport (BigQuery/Snowflake/Fabric service accounts, cloud
  object-store keys, SFTP/FTPS credentials, or the customer's own Shopify/Tradebyte/
  Google Ads/Amazon SP-API tokens) - 7Learnings does not issue a public API key.

schemes:
- id: mcp_oauth2
  type: oauth2
  surface: https://7learnings.com/wp-json/mcp/mcp-oauth-server
  flows:
    authorizationCode:
      authorizationUrl: https://7learnings.com/oauth/authorize
      tokenUrl: https://7learnings.com/oauth/token
      refreshUrl: https://7learnings.com/oauth/token
      revocationUrl: https://7learnings.com/oauth/revoke
      scopes:
        mcp: Access the MCP server surface published by 7learnings.com
  pkce_required_methods: [S256]
  token_endpoint_auth_methods_supported: [none]
  client_registration: >-
    No RFC 7591 dynamic client registration endpoint is advertised. The authorization server
    sets client_id_metadata_document_supported = true, so a client identifies itself with a
    URL to a client-id metadata document rather than a pre-registered client_id.
  bearer_methods_supported: [header]
  evidence: https://7learnings.com/.well-known/oauth-authorization-server
  evidence_status: 200

- id: steering_app_signin
  type: interactive
  surface: 7Learnings Steering App (customer web frontend)
  methods:
  - Single sign-on (SSO)
  - Multi-factor authentication (MFA)
  - Passwordless login
  detail: >-
    "SSO and Multi-Factor Authentication (MFA) support" is stated on the security page;
    the 2026-08-06 changelog entry records that passwordless login and two-factor
    authentication are encouraged for app users.
  evidence: https://7learnings.com/security-compliance-data-protection/
  evidence_status: 200

- id: customer_transport_credentials
  type: delegated
  surface: data integration connectors (inbound and outbound)
  detail: >-
    Each customer connection carries its own credentials for the underlying transport or vendor
    API - BigQuery, Snowflake, Microsoft Fabric, Google Cloud Storage, AWS S3, Azure Blob
    Storage, SFTP, FTPS, HTTPS, and the customer's Shopify, Tradebyte, Plentymarkets,
    commercetools, Scayle, Salesforce Commerce Cloud, Google Ads, Google Shopping, Google
    Analytics, Amazon SP-API and Amazon Ads accounts. No credential shapes, key prefixes or
    header names are published.
  evidence: https://app-static-7l.storage.googleapis.com/latest/7Learnings_initial_data_request.pdf
  evidence_status: 200

key_management:
  customer_managed_encryption_keys: true
  detail: >-
    "Customer-managed encryption keys, allowing clients the ability to immediately delete keys
    to render data unreadable if necessary." Each client is deployed in a dedicated GCP project
    with VPC Service Controls.
  evidence: https://7learnings.com/security-compliance-data-protection/

not_found:
- No public API key issuance or developer key management page
- No /.well-known/openid-configuration (404)
- No documented bearer/HTTP auth for a product REST API

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/7learnings-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.